Improvement

The private agent start command no longer contains your runner key

The docker run command shown when you create a runner key now reads the key from your shell and names a fixed agent release.

When you create a runner key, the dashboard and the CLI show a docker run command for starting an agent. Two things about it have changed.

The key is no longer written into the command. It used to appear as -e RUNNER_API_KEY=rk_..., which left it in your shell history and visible in the process list while Docker started. The command now comes in two steps. The first reads the key into your shell without showing it. The second starts the agent and tells Docker to pick the key up from there. If you skip the first step, the second stops with a message instead of starting an agent that has no key.

The image is a fixed release, not latest. The command names the current agent version together with the digest of its image, so running it again next month starts exactly the same agent. A digest identifies the image contents, so Docker refuses anything else published under that name. To move a docker run agent to a newer release, create a new runner key, which comes with the command for the current version, then remove the old container and revoke the old key. The steps are in Updating the agent.

Agents started with the Compose file are unaffected. Their key was already kept in .env.

The dashboard change is live now. In the CLI it is in @yorker/cli@0.10.2.